Senior Cybersecurity Engineer, Detection Engineer
Marathon Petroleum CorporationAbout the role
An exciting career awaits you
At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.
Position Summary
The Senior Cybersecurity Engineer, Detection Engineer plays a critical role in safeguarding Marathon Petroleum Corporation’s digital and operational assets across enterprise IT and industrial control systems (ICS/OT). This position is responsible for engineering and optimizing threat detection logic to identify, analyze, and respond to emerging cyber threats targeting both business and field operations, including refineries, pipelines, terminals, and remote industrial facilities.
Working as part of the Cyber Threat Operations team within the Cyber Fusion Center, the engineer will translate complex threat intelligence into high-fidelity detection capabilities, develop automated response workflows, and contribute to the ongoing enhancement of incident response playbooks. The role requires close coordination with internal teams including threat hunting, incident response, threat intelligence, and infrastructure to ensure alignment between detection strategy, risk posture, and operational resiliency.
The ideal candidate is technically proficient, collaborative, and mission-driven, with a strong understanding of IT/OT security principles and a passion for protecting critical infrastructure within the energy sector.
Key Responsibilities
- Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess business impact and cybersecurity risk by developing, implementing, and continuously refining cyber threat detection logic across the corporate SIEM/SOAR platform. Resolves complex multi-functional technical issues.
- Leverages cybersecurity assessments, standards and ensures compliance across security systems.
- Improves the efficiency and effectiveness of Security solutions, processes and controls in place by building, testing, and maintaining security automation and orchestration workflows to accelerate detection and response across environments.
- Analyzes existing processes and procedures and leads efforts for implementing improvements or remediation.
- Responsible for development and submission of Standard Operating Procedures.
- Analyzes business impacting events, performs initial investigation. Monitors networks, systems, and applications for signs of potential cybersecurity incidents.
- Investigates and analyzes the nature and scope of cyber incidents. Assists in the development of innovative and creative ideas to formulate risk mitigation and remediation plans and approaches to ensure regulatory compliance by collaborating with threat intelligence and hunting teams to operationalize adversary TTPs into actionable detection use cases.
- Leads implementation of global security initiatives, policies, and compliance requirements. Collects and validates all security metrics and any remediation efforts associated with them.
- Manages cyber security-related consulting, guidance, and support to customers and stakeholders by Documenting detection content, orchestration logic, tuning efforts, and automation workflows for internal knowledge sharing and auditability.
- Translates security principles to assist configuration teams with incorporating security into build and configuration processes.
- Monitors emerging IT/OT and cybersecurity technologies as well as their impact on the security landscape.
Education and Experience
- Bachelor’s Degree in Information Technology, related field or equivalent experience.
- Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred.
- 5+ years of relevant experience required
- Hands-on experience with SIEM platforms (e.g., Splunk, Google SecOps, QRadar), detection rule creation, and alert tuning required.
- Experience with scripting (e.g., Python, PowerShell) and security automation/orchestration tools (e.g., SOAR platforms like Google SecOps, Cortex XSOAR, Splunk SOAR, or Swimlane) required.
- Cybersecurity certifications such as GCDA, GRID, GCIA, GNFA, GCFA or equivalent preferred.
- Familiarity with ICS/OT networks and industrial protocols such as Modbus, DNP3, and OPC preferred.
- Knowledge of threat frameworks including MITRE ATT&CK and Cyber Kill Chain preferred.
- Experience collaborating with cybersecurity, engineering, and operations teams preferred
Skills
- Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue.
- Cybersecurity Risk Management - The process of developing cyb
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s